1
24.7 Production Series / Re: DNS Over TLS Broken
« on: November 22, 2024, 09:32:05 pm »
...works just fine and stable here for years. Why complain?
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
If I have two different interfaces with different subnets there usually is a good reason for this and therefore all (but very limited) traffic between these two interfaces should be blocked. Yes, it needs a block rule, that's **sense 101 ;-)
Well... I have a lots of different subnets. And for some clients the traffic is surely allowed to reach the LAN, depending on the use case of the VLAN/Subnet. But I was still surpised, that its just routed.
Like already mentioned, this is a OPNsense design then. Because with any enterprise FW you do not have this behavior. For a good reason.
But maybe an additional Help-Text would be good to make this clear.
"Only accept connections from the selected interfaces. Leave empty to listen globally. Use with care."
This is definitely not that clear. At least not to me. Because the initial connection was not coming from the LAN interface ingress.
If you know this behavior, sure its clear then.
bunzip2 OPNsense-24.7-vga-amd64.img.bz2